用扩散模型防御语音识别对抗攻击,两步即可完全抵御。
Detecting and Defending Against Adversarial Attacks on Automatic Speech Recognition via Diffusion Models
- 用扩散模型净化含对抗噪声的语音信号
- 仅需2步前向扩散即可完全防御句子级攻击
- 无需训练即可检测对抗攻击,适合安全防护场景
自动语音识别(ASR)系统易受对抗攻击。本文针对针对白盒攻击的语音信号防御问题,系统研究了扩散模型(DMs)在句子级ASR任务中的应用效果。尽管已有工作利用扩散模型在关键词检测任务中取得先进成果,但其在更复杂句子级任务中的表现尚未被探索,且前向扩散步骤数量对性能的影响也缺乏研究。本文在Mozilla Common Voice数据集上开展全面实验,发现仅需两步前向扩散即可完全防御对抗攻击。此外,提出一种无需训练的检测方法,通过预训练扩散模型实现高精度对抗攻击检测。实验验证了该方法的有效性。
原文摘要 · Abstract (English)
Automatic speech recognition (ASR) systems are known to be vulnerable to adversarial attacks. This paper addresses detection and defence against targeted white-box attacks on speech signals for ASR systems. While existing work has utilised diffusion models (DMs) to purify adversarial examples, achieving state-of-the-art results in keyword spotting tasks, their effectiveness for more complex tasks such as sentence-level ASR remains unexplored. Additionally, the impact of the number of forward diffusion steps on performance is not well understood. In this paper, we systematically investigate the use of DMs for defending against adversarial attacks on sentences and examine the effect of varying forward diffusion steps. Through comprehensive experiments on the Mozilla Common Voice dataset, we demonstrate that two forward diffusion steps can completely defend against adversarial attacks on sentences. Moreover, we introduce a novel, training-free approach for detecting adversarial attacks by leveraging a pre-trained DM. Our experimental results show that this method can detect adversarial attacks with high accuracy.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。